2 ms·
> They still need to fix the security issues everyone reimplements every time such as local file disclosure via DTDs, exploding documents due to entity expansio
by xienze 17d ago
> They still need to fix the security issues everyone reimplements every time such as local file disclosure via DTDs, exploding documents due to entity expansion and so on.
Who is doing this reimplementation? You're supposed to be using mature, battle-tested libraries for parsing these formats. Writing your own parser for just about any format is a fool's errand when good implementations that have already addressed these issues exist. Even a simple format like JSON is not immune to performance, safety, and correctness pitfalls.
- throwaway7356 16d agoMany libraries still have unsafe defaults. They come from the XML-age where security concerns were minor (SQL injection was still new to most!) Using XML in a safe way requires you to study what is wrong with XML first. That is not what many people do.